Skip to content

Commit 877817b

Browse files
pin github deps to shas
1 parent d9ae47b commit 877817b

File tree

5 files changed

+22
-22
lines changed

5 files changed

+22
-22
lines changed

.github/workflows/automerge-dependabot.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ jobs:
1111
steps:
1212
- name: Dependabot metadata
1313
id: metadata
14-
uses: dependabot/[email protected]
14+
uses: dependabot/fetch-metadata@08eff52bf64351f401fb50d4972fa95b9f2c2d1b # v2.4.0
1515
with:
1616
github-token: "${{ secrets.GITHUB_TOKEN }}"
1717
- name: Approve Dependabot PRs

.github/workflows/build-docs.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,8 +12,8 @@ jobs:
1212
build-test-deploy:
1313
runs-on: ubuntu-latest
1414
steps:
15-
- uses: actions/checkout@v5
16-
- uses: actions/setup-node@v5
15+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
16+
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
1717
with:
1818
node-version-file: '.nvmrc'
1919

@@ -31,7 +31,7 @@ jobs:
3131

3232
- name: Deploy
3333
if: github.ref == 'refs/heads/main'
34-
uses: JamesIves/github-pages-deploy-action@v4
34+
uses: JamesIves/github-pages-deploy-action@6c2d9db40f9296374acc17b90404b6e8864128c8 # v4.7.3
3535
with:
3636
branch: gh-pages
3737
folder: site

.github/workflows/create-bumb-version-pr.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -17,13 +17,13 @@ jobs:
1717
shell: bash
1818
steps:
1919

20-
- uses: actions/checkout@v5
20+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
2121
with:
2222
fetch-depth: 0
2323
ref: main
2424

2525
- name: Use Node.js from nvmrc
26-
uses: actions/setup-node@v5
26+
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
2727
with:
2828
node-version-file: '.nvmrc'
2929

@@ -33,7 +33,7 @@ jobs:
3333
./build/bump-version-changelog.js ${{ inputs.version }}
3434
3535
- name: Create Pull Request
36-
uses: peter-evans/create-pull-request@v7
36+
uses: peter-evans/create-pull-request@271a8d0340265f705b14b6d32b9829c1cb33d45e # v7.0.8
3737
with:
3838
commit-message: Bump version to ${{ inputs.version }}
3939
branch: bump-version-to-${{ inputs.version }}

.github/workflows/publish-style-spec.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -13,13 +13,13 @@ jobs:
1313
run:
1414
shell: bash
1515
steps:
16-
- uses: actions/checkout@v5
16+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
1717
with:
1818
fetch-depth: 0
1919
ref: main
2020

2121
- name: Use Node.js from nvmrc
22-
uses: actions/setup-node@v5
22+
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
2323
with:
2424
node-version-file: '.nvmrc'
2525

@@ -44,25 +44,25 @@ jobs:
4444
if: ${{ needs.release-check.outputs.publish == 'true' }}
4545
runs-on: ubuntu-latest
4646
steps:
47-
- uses: actions/checkout@v5
47+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
4848
with:
4949
fetch-depth: 0
5050

5151
- name: Use Node.js from nvmrc
52-
uses: actions/setup-node@v5
52+
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
5353
with:
5454
node-version-file: '.nvmrc'
5555
registry-url: 'https://registry.npmjs.org'
5656

5757
- name: Get version
5858
id: package-version
59-
uses: martinbeentjes/[email protected]
59+
uses: martinbeentjes/npm-get-version-action@3cf273023a0dda27efcd3164bdfb51908dd46a5b # v1.3.1
6060

6161
- name: Check tag does not exist yet
6262
run: if git rev-list v${{ steps.package-version.outputs.current-version }}; then echo "Tag already exists. Aborting the release process."; exit 1; fi
6363

6464
- name: Tag commit and push
65-
uses: mathieudutour/[email protected]
65+
uses: mathieudutour/github-tag-action@a22cf08638b34d5badda920f9daf6e72c477b07b # v6.2
6666
with:
6767
github_token: ${{ secrets.GITHUB_TOKEN }}
6868
custom_tag: ${{ steps.package-version.outputs.current-version }}
@@ -95,7 +95,7 @@ jobs:
9595
- name: Create GitHub Release (regular)
9696
id: create_regular_release
9797
if: ${{ steps.prepare_release.outputs.release_type == 'regular' }}
98-
uses: ncipollo/release-action@v1
98+
uses: ncipollo/release-action@b7eabc95ff50cbeeedec83973935c8f306dfcd0b # v1.20.0
9999
env:
100100
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
101101
with:

.github/workflows/test-all.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -16,8 +16,8 @@ jobs:
1616
name: Code Hygiene
1717
runs-on: ubuntu-latest
1818
steps:
19-
- uses: actions/checkout@v5
20-
- uses: actions/setup-node@v5
19+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
20+
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
2121
with:
2222
node-version-file: '.nvmrc'
2323
- run: npm ci
@@ -29,15 +29,15 @@ jobs:
2929
name: Unit and Integration Tests
3030
runs-on: ubuntu-latest
3131
steps:
32-
- uses: actions/checkout@v5
33-
- uses: actions/setup-node@v5
32+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
33+
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
3434
with:
3535
node-version-file: '.nvmrc'
3636
- run: npm ci
3737
- run: npm run test-unit-ci
3838
- run: npm run test-integration-ci
3939
- name: Upload coverage reports to Codecov
40-
uses: codecov/codecov-action@v5
40+
uses: codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7 # v5.5.1
4141
with:
4242
files: ${{ github.workspace }}/coverage/vitest/unit/coverage-final.json, ${{ github.workspace }}/coverage/vitest/integration/coverage-final.json
4343
verbose: true
@@ -50,8 +50,8 @@ jobs:
5050
os: [ubuntu-latest, windows-latest]
5151
runs-on: ${{ matrix.os }}
5252
steps:
53-
- uses: actions/checkout@v5
54-
- uses: actions/setup-node@v5
53+
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
54+
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
5555
with:
5656
node-version-file: '.nvmrc'
5757
- run: npm ci
@@ -60,7 +60,7 @@ jobs:
6060
- run: npm run build
6161
- run: npm run test-build-ci
6262
- name: Upload coverage reports to Codecov
63-
uses: codecov/codecov-action@v5
63+
uses: codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7 # v5.5.1
6464
with:
6565
files: ${{ github.workspace }}/coverage/vitest/build/coverage-final.json
6666
verbose: true

0 commit comments

Comments
 (0)